Out-of-bounds read in SDL_image - CVE-2026-35444
Published: April 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to out-of-bounds read in do_layer_surface() in src/IMG_xcf.c when parsing a crafted .xcf file containing out-of-range colormap indices. A remote attacker can trick the victim into opening a crafted file to disclose sensitive information.
The leaked heap bytes are written into the output surface pixel data and may be observable in the rendered image.
Affected software
Fedora
SDL2_image
mingw-SDL2_image
SDL3_image
How to mitigate CVE-2026-35444
SDL2_image - addressed in versions 2.8.12-1.el9, 2.8.12-1.el10_1, 2.8.12-1.el10_2, 2.8.12-1.el10_3, 2.8.12-1.fc42, 2.8.12-1.fc43, 2.8.12-1.fc44
mingw-SDL2_image - addressed in versions 2.8.12-1.fc43, 2.8.12-1.fc44
SDL3_image - addressed in versions 3.4.4-1.fc43, 3.4.4-1.fc44
External References
Related Security Bulletins
- Information disclosure in SDL_image
- Fedora 44 update for SDL3_image
- Fedora 43 update for SDL3_image
- Fedora EPEL 10.1 update for SDL2_image
- Fedora 43 update for SDL2_image
- Fedora EPEL 9 update for SDL2_image
- Fedora EPEL 10.3 update for SDL2_image
- Fedora 44 update for SDL2_image
- Fedora EPEL 10.2 update for SDL2_image
- Fedora 42 update for SDL2_image
- Fedora 44 update for mingw-SDL2_image
- Fedora 43 update for mingw-SDL2_image